Cookie Consent by Free Privacy Policy Generator ๐Ÿ“Œ [Slide] The Kelihos & Severa; the "All Out" version

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š [Slide] The Kelihos & Severa; the "All Out" version


๐Ÿ’ก Newskategorie: Malware / Trojaner / Viren
๐Ÿ”— Quelle: blog.malwaremustdie.org

Background

The "suspected actor" in the below slide is responsible for malware distribution via RedKit exploit kit [-1-] [-2-] [-3-], Cookie Bomb [-1-] [-2-] [-3-] [-4-], Malicious Cushion Redirectors [-1-], and those all linked and lead to his botnet the Kelihos a fast flux botnet [-1-] [-2-] [-3-]. The actor is known as Petr Severa.

When I went to Botconf in December 2013, I was spending much time in my secluded hotel room (I stayed separately than others) than in conference so I can focus to this important disclosure, that our team is depending on me to reveal it well during the Short Talk chance that was generously and thankfully given for this matter. These are the materials that I looked over and over like hundred times, with thinking of which one that is needed to be shared in conference, which one that has to be shared to law enforcement only, and what information that is needed to be shared to friend-researchers.

After discussed with our MalwareMustDie team the night before, and several discussion with the important persons, fyi: at that time the Kelihos CNC in Nederlands were successfully taken down my our friend from McAfee, Mr. Christiaan Beek, and our Germany team lead by wirehack7 together with LKA was in literally raiding the CNC machines of Kelihos CNC from its data center.. It was the crazy busy and hard time for a jet-lagged-guy from Japan who got very tired from travel via Paris airport for 7hrs (stuck in AirPort for long long lines), and slept in front door of hotel all night since the door was locked when I arrived at 11pm.. I selected the slides that was shared in-->[link] that I rehearsed with Mr. Dhia Mahjoub of OpenDNS, the pair presenter.

Soon it will be three full years since the first time I decompiled our first Kelihos botnet Win32 binary, and with all due respect to great good hard working people in many security incident response entities, internet administration and law enforcement teams, nothing has been changed much in this three years, the actor is still out there receiving his monthly affiliated "fee" and living happily with still practicing his unique modus operandi to spread the badness in the internet. We still see Kelihos is distributed along with ransomware, and we still see cookie bomb codes is used to spread malware & also ransomware too.

Slide

On some data that I starred in the hotel room, these are the data collected from our operation against this botnet (excluded Dhia's OpenDNS data), there are a very important PoC or evidence as as malicious verdict to a known internet crime bandit from St. Petersburg, the "Severa". I recollect them all in this slide with adding all re-compiled and renewed comments with more supporting facts.

Our team was patiently waiting for the justification of the crime done by known identification, but as one of our member just said "I think that full disclosure after 2,5years is pretty reasonable.." (poke @Kira), this is the best team for fighting any botnet on earth..I am happy to work with them, and I think the world to know what they actually achieved and who, how and why we know the ID of the botherder that leads to the mentioned actor.

Here is the slide:

Please use the data with the right way. All of the evidence mentioned were found in the internet or dumps.

#MalwareMustDie

...













๐Ÿ“Œ [Slide] The Kelihos & Severa; the "All Out" version


๐Ÿ“ˆ 86.37 Punkte

๐Ÿ“Œ [Slide|Video] Kelihos & Peter Severa; the "All Out" version


๐Ÿ“ˆ 86.37 Punkte

๐Ÿ“Œ [Slide|Video] Kelihos & Peter Severa; the "All Out" version


๐Ÿ“ˆ 86.37 Punkte

๐Ÿ“Œ [Slide] The Kelihos & Severa; the "All Out" version


๐Ÿ“ˆ 86.37 Punkte

๐Ÿ“Œ [Slide|Video] Kelihos & Peter Severa; the "All Out" version


๐Ÿ“ˆ 86.37 Punkte

๐Ÿ“Œ Tribulant Slideshow Gallery Plugin 1.6.8 on WordPress admin.php Slide[title]/Slide[media_file]/Slide[image_url] cross site scripting


๐Ÿ“ˆ 52.89 Punkte

๐Ÿ“Œ Tribulant Slideshow Gallery Plugin 1.6.8 on WordPress admin.php Slide[title]/Slide[media_file]/Slide[image_url] cross site scripting


๐Ÿ“ˆ 52.89 Punkte

๐Ÿ“Œ t3n Daily: Adobe & Figma, Ethereum & NFT, Steuer & Homeoffice, KI & Gruselfrau


๐Ÿ“ˆ 28.3 Punkte

๐Ÿ“Œ iPhone 12 Flip im Video: Freut euch auf "slide to unfold"


๐Ÿ“ˆ 22.35 Punkte

๐Ÿ“Œ http://umkm.padang.go.id/index.php?option=com_content&view=article&id=46&Itemid=78


๐Ÿ“ˆ 21.23 Punkte

๐Ÿ“Œ http://swat.sragenkab.go.id/index.php?option=com_content&view=article&id=76&Itemid=27


๐Ÿ“ˆ 21.23 Punkte

๐Ÿ“Œ MMD-0046-2015 - (Recent and new) Kelihos CNC activity XXXX(censored)


๐Ÿ“ˆ 21.17 Punkte

๐Ÿ“Œ Regarding Kelihos Research


๐Ÿ“ˆ 21.17 Punkte

๐Ÿ“Œ Significant Increase in Kelihos Botnet Activity


๐Ÿ“ˆ 21.17 Punkte

๐Ÿ“Œ Kelihos Botnet Triples Its Size in Just 24 Hours


๐Ÿ“ˆ 21.17 Punkte

๐Ÿ“Œ MMD-0046-2015 - (Recent and new) Kelihos CNC activity XXXX(censored)


๐Ÿ“ˆ 21.17 Punkte

๐Ÿ“Œ Significant Increase in Kelihos Botnet Activity


๐Ÿ“ˆ 21.17 Punkte

๐Ÿ“Œ Kelihos Botnet Triples Its Size in Just 24 Hours


๐Ÿ“ˆ 21.17 Punkte

๐Ÿ“Œ Kelihos Analysis - Part 1


๐Ÿ“ˆ 21.17 Punkte

๐Ÿ“Œ US targets Kelihos botnet after Russian's arrest in Spain


๐Ÿ“ˆ 21.17 Punkte

๐Ÿ“Œ Kelihos Analysis - Part 1


๐Ÿ“ˆ 21.17 Punkte

๐Ÿ“Œ Spanish cops snatch suspected top spammer as US moves against Kelihos botnet


๐Ÿ“ˆ 21.17 Punkte

๐Ÿ“Œ Regarding Kelihos Research


๐Ÿ“ˆ 21.17 Punkte

๐Ÿ“Œ Kelihos Spreads via USB Drives


๐Ÿ“ˆ 21.17 Punkte

๐Ÿ“Œ Kelihos Becomes King of the Malware Mountain


๐Ÿ“ˆ 21.17 Punkte

๐Ÿ“Œ Nach Hacker-Festnahme: FBI will Kelihos-Botnetz endgรผltig stilllegen


๐Ÿ“ˆ 21.17 Punkte

๐Ÿ“Œ Nach Hacker-Festnahme: FBI will Kelihos-Botnetz endgรผltig stilllegen


๐Ÿ“ˆ 21.17 Punkte

๐Ÿ“Œ Spammerโ€™s Arrest Puts End to Kelihos Botnet


๐Ÿ“ˆ 21.17 Punkte

๐Ÿ“Œ The Kelihos Botnet


๐Ÿ“ˆ 21.17 Punkte

๐Ÿ“Œ Alleged Kelihos Botnet Author Arrested in Spain


๐Ÿ“ˆ 21.17 Punkte

๐Ÿ“Œ Feds Start Dismantling Kelihos Botnet After Russian Hacker's Arrest in Spain


๐Ÿ“ˆ 21.17 Punkte

๐Ÿ“Œ U.S. Takes Down Kelihos Botnet After Its Russian Operator Arrested in Spain


๐Ÿ“ˆ 21.17 Punkte

๐Ÿ“Œ Russian Hacker Behind Kelihos Botnet Indicted in US


๐Ÿ“ˆ 21.17 Punkte

matomo